Unauthorized access to files in T-Systems products

Posted date 16/06/2026
Identificador
INCIBE-2026-428
Importance
3 - Medium
Affected Resources

The following products in the TAO 2.0 suite, in versions prior to 2602.00, are affected:

  • Archivo;
  • MyTAO;
  • eStima;
  • Buroweb.
Description

INCIBE has coordinated the disclosure of a medium-severity vulnerability affecting several products in the TAO 2.0 suite, a management platform for public administration. The vulnerability was discovered by T-Systems’ internal security team.

This vulnerability has been assigned the following identifier, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type:

  • CVE-2026-7185: CVSS v4.0: 6.0 | CVSS AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N | CWE-22
Solution

The vulnerability, reported by the T-Systems team itself, has been fixed in version 2602.0.0 of the affected products. The general recommendation is to update to that version or any later version that includes these fixes.

Detail

CVE-2026-7185: a validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite. This vulnerability could allow an attacker capable of interacting with the affected feature to attempt to access file system resources outside the scope intended by the application.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-7185 Media No T-Systems
References list